|
|
grahalex
regular
Reg'd: Sat
Posts: 45
|
Re: Blue Screen - please check log
Mon Mar 31 2008 09:53 PM
|
|
|
"Graham" - 2008-03-31 21:46:02 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-31 )))))))))))))))))))))))))))))))
2008-03-31 03:27 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys 2008-03-31 03:27 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys 2008-03-31 03:19 63,488 --a------ C:\WINDOWS\xobglu16.dll 2008-03-31 03:19 23,552 --a------ C:\WINDOWS\xobglu32.dll 2008-03-30 14:00 <DIR> d-------- C:\DOCUME~1\Graham\APPLIC~1\The Labyrinth Plus! Edition 2008-03-30 13:54 98,304 --a------ C:\WINDOWS\system32\ImmPID.dll 2008-03-30 13:54 29,372 --a------ C:\WINDOWS\system32\drivers\ImHidUsb.sys 2008-03-30 13:54 192,512 --a------ C:\WINDOWS\system32\IFC22.dll 2008-03-30 13:54 16,384 --a------ C:\WINDOWS\system32\imm_enu.dll 2008-03-30 13:54 1,024,000 --a------ C:\WINDOWS\system32\ImmCpl.dll 2008-03-30 13:54 <DIR> d-------- C:\Program Files\Saitek 2008-03-30 12:59 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT 2008-03-29 18:40 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Barbie Fashion Show 2008-03-29 18:38 <DIR> d-------- C:\Program Files\Common Files\Vivendi Universal Games 2008-03-29 18:38 <DIR> d-------- C:\Program Files\Barbie(TM) 2008-03-29 17:31 4,096 --a------ C:\DOCUME~1\Graham\DesktopTrojan.Win32.BlackBird.exe 2008-03-29 17:31 4,096 --a------ C:\DOCUME~1\Graham\DesktopFWebdEditor.exe 2008-03-29 17:31 4,096 --a------ C:\DOCUME~1\Graham\Desktopfwebd.exe 2008-03-29 17:31 4,096 --a------ C:\DOCUME~1\Graham\Desktopfkwp2.0.exe 2008-03-29 17:31 4,096 --a------ C:\DOCUME~1\Graham\Desktopfkwp1.5.exe 2008-03-29 17:31 4,096 --a------ C:\DOCUME~1\Graham\Desktopfilemanagerclient.exe 2008-03-29 17:31 4,096 --a------ C:\DOCUME~1\Graham\DesktopEditorFKWP2.0.exe 2008-03-29 17:31 4,096 --a------ C:\DOCUME~1\Graham\DesktopEditorFKWP1.5.exe 2008-03-29 17:31 <DIR> d-------- C:\DOCUME~1\Graham\Desktopvirii 2008-03-29 15:27 4,096 --a------ C:\DOCUME~1\CATHER~1\DesktopTrojan.Win32.BlackBird.exe 2008-03-29 15:27 4,096 --a------ C:\DOCUME~1\CATHER~1\DesktopFWebdEditor.exe 2008-03-29 15:27 4,096 --a------ C:\DOCUME~1\CATHER~1\Desktopfwebd.exe 2008-03-29 15:27 4,096 --a------ C:\DOCUME~1\CATHER~1\Desktopfkwp2.0.exe 2008-03-29 15:27 4,096 --a------ C:\DOCUME~1\CATHER~1\Desktopfkwp1.5.exe 2008-03-29 15:27 4,096 --a------ C:\DOCUME~1\CATHER~1\Desktopfilemanagerclient.exe 2008-03-29 15:27 4,096 --a------ C:\DOCUME~1\CATHER~1\DesktopEditorFKWP2.0.exe 2008-03-29 15:27 4,096 --a------ C:\DOCUME~1\CATHER~1\DesktopEditorFKWP1.5.exe 2008-03-29 15:27 <DIR> d-------- C:\DOCUME~1\CATHER~1\Desktopvirii 2008-03-29 14:55 94,208 --a------ C:\WINDOWS\system32\uhelgdsv.exe 2008-03-29 14:34 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\fhhjytzh 2008-03-29 14:04 32,256 --a------ C:\WINDOWS\system32\drivers\w2wtime.sys 2008-03-29 14:04 12,800 --a------ C:\WINDOWS\system32\drivers\wtcls2k.sys 2008-03-29 14:04 114,688 --a------ C:\WINDOWS\system32\wintab32.exe 2008-03-29 14:04 <DIR> d-------- C:\WINDOWS\Wintime 2008-03-29 13:50 94,208 --a------ C:\WINDOWS\system32\ncxudivg.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\winsystem.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\userconfig9x.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32WINWGPX.EXE 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32winsystem.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32winlogonpc.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32vcatchpi.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32vbsys2.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32thun32.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32thun.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32temp#01.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32taack.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32taack.dat 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32sysreq.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32ssvchost.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32ssvchost.com 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32ssurf022.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32sncntr.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32Rundl1.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32regm64.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32regc64.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32psoft1.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32psof1.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32ps1.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32newsd32.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32netode.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32mwin32.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32mtr2.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32msvchost.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32mssecu.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32msnbho.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32msgp.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32medup020.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32medup012.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32hxiwlgpm.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32hxiwlgpm.dat 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32hoproxy.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32h@tkeysh@@k.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32emesx.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32dpcproxy.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32bsva-egihsg52.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32bdn.com 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32awtoolb.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32anticipator.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32akttzn.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\mssecu.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\iTunesMusic.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\FVProtect.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\bdn.com 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\a.bat 2008-03-29 13:50 4,096 --a------ C:\DOCUME~1\Annette\DesktopTrojan.Win32.BlackBird.exe 2008-03-29 13:50 4,096 --a------ C:\DOCUME~1\Annette\DesktopFWebdEditor.exe 2008-03-29 13:50 4,096 --a------ C:\DOCUME~1\Annette\Desktopfwebd.exe 2008-03-29 13:50 4,096 --a------ C:\DOCUME~1\Annette\Desktopfkwp2.0.exe 2008-03-29 13:50 4,096 --a------ C:\DOCUME~1\Annette\Desktopfkwp1.5.exe 2008-03-29 13:50 4,096 --a------ C:\DOCUME~1\Annette\Desktopfilemanagerclient.exe 2008-03-29 13:50 4,096 --a------ C:\DOCUME~1\Annette\DesktopEditorFKWP2.0.exe 2008-03-29 13:50 4,096 --a------ C:\DOCUME~1\Annette\DesktopEditorFKWP1.5.exe 2008-03-29 13:50 <DIR> d-------- C:\WINDOWS\system32smp 2008-03-29 13:50 <DIR> d-------- C:\DOCUME~1\Annette\Desktopvirii 2008-03-29 11:47 <DIR> d-------- C:\Program Files\WinTime
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-03-31 20:49:33 -------- d-----w C:\Program Files\Firefly Media Server 2008-03-31 20:48:37 51,075,104 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat 2008-03-31 18:13:31 599,576 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx 2008-03-30 12:54:39 -------- d--h--w C:\Program Files\InstallShield Installation Information 2008-03-30 10:15:37 -------- d-----w C:\Program Files\Elaborate Bytes 2008-03-29 20:29:18 -------- d-----w C:\Program Files\Common Files\Knowledge Adventure 2008-03-29 17:45:49 1,146,232 ----a-w C:\WINDOWS\system32\aswBoot.exe 2008-03-29 17:35:21 94,544 -c--a-w C:\WINDOWS\system32\drivers\aswmon2.sys 2008-03-29 17:29:08 23,152 -c--a-w C:\WINDOWS\system32\drivers\aswRdr.sys 2008-03-29 17:27:33 42,912 -c--a-w C:\WINDOWS\system32\drivers\aswTdi.sys 2008-03-29 17:26:52 26,944 -c--a-w C:\WINDOWS\system32\drivers\aavmker4.sys 2008-03-29 17:23:22 95,608 -c--a-w C:\WINDOWS\system32\AvastSS.scr 2008-03-27 08:26:37 -------- d-----w C:\DOCUME~1\Graham\APPLIC~1\LimeWire 2008-03-22 09:34:18 -------- d-----w C:\DOCUME~1\Graham\APPLIC~1\WeatherWatcher 2008-03-22 09:31:33 -------- d-----w C:\Program Files\Weather Watcher 2008-03-21 10:07:08 -------- d-----w C:\Program Files\EPSON 2008-03-21 06:22:35 -------- d-----w C:\Program Files\Google 2008-03-20 20:54:54 -------- d-----w C:\Program Files\Windows Live 2008-03-20 20:38:59 -------- d-----w C:\Program Files\TweakNow RegCleaner Std 2008-03-20 20:38:59 -------- d-----w C:\Program Files\SimpleDivX 2008-03-20 20:38:59 -------- d-----w C:\Program Files\Roku Radio Snooper 2008-03-20 20:38:53 -------- d-----w C:\Program Files\MP3 Remix 2008-03-20 20:38:46 -------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller 2008-03-20 20:38:46 -------- d-----w C:\Program Files\DivX 2008-03-20 20:38:46 -------- d-----w C:\Program Files\Common Files\Nullsoft 2008-03-20 20:38:43 -------- d-----w C:\Program Files\Common Files\aolshare 2008-03-20 20:38:39 -------- d-----w C:\Program Files\Apple Software Update 2008-03-20 20:38:39 -------- d-----w C:\Program Files\AOL 9.0 2008-03-19 15:14:57 -------- d-----w C:\Program Files\RogueRemover FREE 2008-03-17 18:51:41 -------- d-----w C:\Program Files\SpywareBlaster 2008-03-13 16:36:18 -------- d-----w C:\Program Files\IObit 2008-03-09 10:30:42 -------- d-----w C:\DOCUME~1\Graham\APPLIC~1\ZipGenius 2008-03-07 21:19:33 -------- d-----w C:\DOCUME~1\Graham\APPLIC~1\RipIt4Me 2008-02-28 19:36:48 -------- d-----w C:\Program Files\BitComet 2008-02-26 16:23:29 -------- d-----w C:\Program Files\i-Sound Pro 2008-02-19 19:56:54 13,568 -c--a-w C:\WINDOWS\system32\drivers\USBCRFT.SYS 2008-02-16 09:50:47 -------- d-----w C:\Program Files\LimeWire 2008-01-31 15:52:57 -------- d-----w C:\DOCUME~1\Graham\APPLIC~1\Sereniti 2008-01-18 14:43:49 12,632 -c--a-w C:\WINDOWS\system32\lsdelete.exe 2008-01-06 10:37:16 60,416 -c--a-w C:\WINDOWS\ALCFDRTM.EXE 2008-01-04 21:59:04 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe 2008-01-04 21:58:50 3,596,288 -c--a-w C:\WINDOWS\system32\qt-dx331.dll 2008-01-04 21:58:42 200,704 -c--a-w C:\WINDOWS\system32\ssldivx.dll 2008-01-04 21:58:42 1,044,480 -c--a-w C:\WINDOWS\system32\libdivx.dll 2008-01-04 21:57:22 81,920 -c--a-w C:\WINDOWS\system32\dpl100.dll 2008-01-04 21:57:22 196,608 -c--a-w C:\WINDOWS\system32\dtu100.dll 2008-01-04 21:57:16 53,248 -c--a-w C:\WINDOWS\system32\dpuGUI10.dll 2008-01-04 21:57:14 593,920 -c--a-w C:\WINDOWS\system32\dpuGUI11.dll 2008-01-04 21:57:14 57,344 -c--a-w C:\WINDOWS\system32\dpv11.dll 2008-01-04 21:57:14 344,064 -c--a-w C:\WINDOWS\system32\dpus11.dll 2008-01-04 21:57:14 294,912 -c--a-w C:\WINDOWS\system32\dpu11.dll 2008-01-04 21:57:14 294,912 -c--a-w C:\WINDOWS\system32\dpu10.dll 2008-01-04 21:57:12 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll 2008-01-04 21:57:10 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll 2008-01-04 21:57:10 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll 2008-01-04 21:57:10 682,496 ----a-w C:\WINDOWS\system32\DivX.dll 2008-01-04 21:56:48 156,992 -c--a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe 2008-01-04 21:56:24 12,288 -c--a-w C:\WINDOWS\system32\DivXWMPExtType.dll 2008-01-01 13:39:58 46 -c--a-w C:\WINDOWS\system32\DonationCoder_rokusnooper_InstallInfo.dat
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] 2006-10-23 00:08 62080 --a------ C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}] 2007-09-28 14:30 521528 --a--c--- C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}] 2008-01-04 18:21 1548624 --a------ C:\PROGRA~1\SPYBOT~1\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] 2007-09-25 01:11 501136 --a--c--- C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] 2007-12-14 13:54 392240 --a------ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}] 2006-08-20 19:55 81920 --a--c--- C:\Program Files\Free Download Manager\iefdmcks.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 18:37] "HostManager"="C:\Program Files\Common Files\AOL\1179865871\ee\AOLSoftware.exe" [2006-11-17 14:21] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11] "IntelliType"="C:\Program Files\Microsoft Hardware\Keyboard\type32.exe" [2002-03-22 05:41] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25] "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 17:05] "IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 16:52] "CICache"="CICache.exe" [2002-09-05 15:21 C:\WINDOWS\CICache.exe] "SmartRAM"="C:\Program Files\IObit\Advanced WindowsCare V2\MemCleaner.exe" [2007-10-29 17:43] "SmartDefrag"="C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" [2008-01-08 00:29] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-06-18 18:11] "SAITEKAUTOCONFIGURE"="C:\Program Files\Saitek\ST\Drv\saicnfig.exe" [] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56] "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "LinkResolveIgnoreLinkInfo"=0 (0x0) "NoResolveSearch"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "LinkResolveIgnoreLinkInfo"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 13:29]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages :\WINDOWS\syste
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
Contents of the 'Scheduled Tasks' folder 2008-03-11 20:07:01 C:\WINDOWS\tasks\AppleSoftwareUpdate.job 2008-03-30 21:00:00 C:\WINDOWS\tasks\SmartDefrag.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2008-03-31 21:49:02 Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully hidden files: 0
**************************************************************************
Completion time: 2008-03-31 21:50:00 C:\ComboFix2.txt ... 2008-03-29 17:54 C:\ComboFix3.txt ... 2008-03-14 21:09
--- E O F --- "Graham" - 2008-03-31 21:46:02 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-31 )))))))))))))))))))))))))))))))
2008-03-31 03:27 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys 2008-03-31 03:27 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys 2008-03-31 03:19 63,488 --a------ C:\WINDOWS\xobglu16.dll 2008-03-31 03:19 23,552 --a------ C:\WINDOWS\xobglu32.dll 2008-03-30 14:00 <DIR> d-------- C:\DOCUME~1\Graham\APPLIC~1\The Labyrinth Plus! Edition 2008-03-30 13:54 98,304 --a------ C:\WINDOWS\system32\ImmPID.dll 2008-03-30 13:54 29,372 --a------ C:\WINDOWS\system32\drivers\ImHidUsb.sys 2008-03-30 13:54 192,512 --a------ C:\WINDOWS\system32\IFC22.dll 2008-03-30 13:54 16,384 --a------ C:\WINDOWS\system32\imm_enu.dll 2008-03-30 13:54 1,024,000 --a------ C:\WINDOWS\system32\ImmCpl.dll 2008-03-30 13:54 <DIR> d-------- C:\Program Files\Saitek 2008-03-30 12:59 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT 2008-03-29 18:40 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Barbie Fashion Show 2008-03-29 18:38 <DIR> d-------- C:\Program Files\Common Files\Vivendi Universal Games 2008-03-29 18:38 <DIR> d-------- C:\Program Files\Barbie(TM) 2008-03-29 17:31 4,096 --a------ C:\DOCUME~1\Graham\DesktopTrojan.Win32.BlackBird.exe 2008-03-29 17:31 4,096 --a------ C:\DOCUME~1\Graham\DesktopFWebdEditor.exe 2008-03-29 17:31 4,096 --a------ C:\DOCUME~1\Graham\Desktopfwebd.exe 2008-03-29 17:31 4,096 --a------ C:\DOCUME~1\Graham\Desktopfkwp2.0.exe 2008-03-29 17:31 4,096 --a------ C:\DOCUME~1\Graham\Desktopfkwp1.5.exe 2008-03-29 17:31 4,096 --a------ C:\DOCUME~1\Graham\Desktopfilemanagerclient.exe 2008-03-29 17:31 4,096 --a------ C:\DOCUME~1\Graham\DesktopEditorFKWP2.0.exe 2008-03-29 17:31 4,096 --a------ C:\DOCUME~1\Graham\DesktopEditorFKWP1.5.exe 2008-03-29 17:31 <DIR> d-------- C:\DOCUME~1\Graham\Desktopvirii 2008-03-29 15:27 4,096 --a------ C:\DOCUME~1\CATHER~1\DesktopTrojan.Win32.BlackBird.exe 2008-03-29 15:27 4,096 --a------ C:\DOCUME~1\CATHER~1\DesktopFWebdEditor.exe 2008-03-29 15:27 4,096 --a------ C:\DOCUME~1\CATHER~1\Desktopfwebd.exe 2008-03-29 15:27 4,096 --a------ C:\DOCUME~1\CATHER~1\Desktopfkwp2.0.exe 2008-03-29 15:27 4,096 --a------ C:\DOCUME~1\CATHER~1\Desktopfkwp1.5.exe 2008-03-29 15:27 4,096 --a------ C:\DOCUME~1\CATHER~1\Desktopfilemanagerclient.exe 2008-03-29 15:27 4,096 --a------ C:\DOCUME~1\CATHER~1\DesktopEditorFKWP2.0.exe 2008-03-29 15:27 4,096 --a------ C:\DOCUME~1\CATHER~1\DesktopEditorFKWP1.5.exe 2008-03-29 15:27 <DIR> d-------- C:\DOCUME~1\CATHER~1\Desktopvirii 2008-03-29 14:55 94,208 --a------ C:\WINDOWS\system32\uhelgdsv.exe 2008-03-29 14:34 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\fhhjytzh 2008-03-29 14:04 32,256 --a------ C:\WINDOWS\system32\drivers\w2wtime.sys 2008-03-29 14:04 12,800 --a------ C:\WINDOWS\system32\drivers\wtcls2k.sys 2008-03-29 14:04 114,688 --a------ C:\WINDOWS\system32\wintab32.exe 2008-03-29 14:04 <DIR> d-------- C:\WINDOWS\Wintime 2008-03-29 13:50 94,208 --a------ C:\WINDOWS\system32\ncxudivg.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\winsystem.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\userconfig9x.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32WINWGPX.EXE 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32winsystem.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32winlogonpc.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32vcatchpi.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32vbsys2.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32thun32.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32thun.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32temp#01.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32taack.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32taack.dat 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32sysreq.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32ssvchost.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32ssvchost.com 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32ssurf022.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32sncntr.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32Rundl1.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32regm64.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32regc64.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32psoft1.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32psof1.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32ps1.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32newsd32.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32netode.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32mwin32.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32mtr2.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32msvchost.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32mssecu.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32msnbho.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32msgp.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32medup020.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32medup012.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32hxiwlgpm.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32hxiwlgpm.dat 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32hoproxy.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32h@tkeysh@@k.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32emesx.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32dpcproxy.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32bsva-egihsg52.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32bdn.com 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32awtoolb.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32anticipator.dll 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\system32akttzn.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\mssecu.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\iTunesMusic.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\FVProtect.exe 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\bdn.com 2008-03-29 13:50 4,096 --a------ C:\WINDOWS\a.bat 2008-03-29 13:50 4,096 --a------ C:\DOCUME~1\Annette\DesktopTrojan.Win32.BlackBird.exe 2008-03-29 13:50 4,096 --a------ C:\DOCUME~1\Annette\DesktopFWebdEditor.exe 2008-03-29 13:50 4,096 --a------ C:\DOCUME~1\Annette\Desktopfwebd.exe 2008-03-29 13:50 4,096 --a------ C:\DOCUME~1\Annette\Desktopfkwp2.0.exe 2008-03-29 13:50 4,096 --a------ C:\DOCUME~1\Annette\Desktopfkwp1.5.exe 2008-03-29 13:50 4,096 --a------ C:\DOCUME~1\Annette\Desktopfilemanagerclient.exe 2008-03-29 13:50 4,096 --a------ C:\DOCUME~1\Annette\DesktopEditorFKWP2.0.exe 2008-03-29 13:50 4,096 --a------ C:\DOCUME~1\Annette\DesktopEditorFKWP1.5.exe 2008-03-29 13:50 <DIR> d-------- C:\WINDOWS\system32smp 2008-03-29 13:50 <DIR> d-------- C:\DOCUME~1\Annette\Desktopvirii 2008-03-29 11:47 <DIR> d-------- C:\Program Files\WinTime
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-03-31 20:49:33 -------- d-----w C:\Program Files\Firefly Media Server 2008-03-31 20:48:37 51,075,104 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat 2008-03-31 18:13:31 599,576 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx 2008-03-30 12:54:39 -------- d--h--w C:\Program Files\InstallShield Installation Information 2008-03-30 10:15:37 -------- d-----w C:\Program Files\Elaborate Bytes 2008-03-29 20:29:18 -------- d-----w C:\Program Files\Common Files\Knowledge Adventure 2008-03-29 17:45:49 1,146,232 ----a-w C:\WINDOWS\system32\aswBoot.exe 2008-03-29 17:35:21 94,544 -c--a-w C:\WINDOWS\system32\drivers\aswmon2.sys 2008-03-29 17:29:08 23,152 -c--a-w C:\WINDOWS\system32\drivers\aswRdr.sys 2008-03-29 17:27:33 42,912 -c--a-w C:\WINDOWS\system32\drivers\aswTdi.sys 2008-03-29 17:26:52 26,944 -c--a-w C:\WINDOWS\system32\drivers\aavmker4.sys 2008-03-29 17:23:22 95,608 -c--a-w C:\WINDOWS\system32\AvastSS.scr 2008-03-27 08:26:37 -------- d-----w C:\DOCUME~1\Graham\APPLIC~1\LimeWire 2008-03-22 09:34:18 -------- d-----w C:\DOCUME~1\Graham\APPLIC~1\WeatherWatcher 2008-03-22 09:31:33 -------- d-----w C:\Program Files\Weather Watcher 2008-03-21 10:07:08 -------- d-----w C:\Program Files\EPSON 2008-03-21 06:22:35 -------- d-----w C:\Program Files\Google 2008-03-20 20:54:54 -------- d-----w C:\Program Files\Windows Live 2008-03-20 20:38:59 -------- d-----w C:\Program Files\TweakNow RegCleaner Std 2008-03-20 20:38:59 -------- d-----w C:\Program Files\SimpleDivX 2008-03-20 20:38:59 -------- d-----w C:\Program Files\Roku Radio Snooper 2008-03-20 20:38:53 -------- d-----w C:\Program Files\MP3 Remix 2008-03-20 20:38:46 -------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller 2008-03-20 20:38:46 -------- d-----w C:\Program Files\DivX 2008-03-20 20:38:46 -------- d-----w C:\Program Files\Common Files\Nullsoft 2008-03-20 20:38:43 -------- d-----w C:\Program Files\Common Files\aolshare 2008-03-20 20:38:39 -------- d-----w C:\Program Files\Apple Software Update 2008-03-20 20:38:39 -------- d-----w C:\Program Files\AOL 9.0 2008-03-19 15:14:57 -------- d-----w C:\Program Files\RogueRemover FREE 2008-03-17 18:51:41 -------- d-----w C:\Program Files\SpywareBlaster 2008-03-13 16:36:18 -------- d-----w C:\Program Files\IObit 2008-03-09 10:30:42 -------- d-----w C:\DOCUME~1\Graham\APPLIC~1\ZipGenius 2008-03-07 21:19:33 -------- d-----w C:\DOCUME~1\Graham\APPLIC~1\RipIt4Me 2008-02-28 19:36:48 -------- d-----w C:\Program Files\BitComet 2008-02-26 16:23:29 -------- d-----w C:\Program Files\i-Sound Pro 2008-02-19 19:56:54 13,568 -c--a-w C:\WINDOWS\system32\drivers\USBCRFT.SYS 2008-02-16 09:50:47 -------- d-----w C:\Program Files\LimeWire 2008-01-31 15:52:57 -------- d-----w C:\DOCUME~1\Graham\APPLIC~1\Sereniti 2008-01-18 14:43:49 12,632 -c--a-w C:\WINDOWS\system32\lsdelete.exe 2008-01-06 10:37:16 60,416 -c--a-w C:\WINDOWS\ALCFDRTM.EXE 2008-01-04 21:59:04 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe 2008-01-04 21:58:50 3,596,288 -c--a-w C:\WINDOWS\system32\qt-dx331.dll 2008-01-04 21:58:42 200,704 -c--a-w C:\WINDOWS\system32\ssldivx.dll 2008-01-04 21:58:42 1,044,480 -c--a-w C:\WINDOWS\system32\libdivx.dll 2008-01-04 21:57:22 81,920 -c--a-w C:\WINDOWS\system32\dpl100.dll 2008-01-04 21:57:22 196,608 -c--a-w C:\WINDOWS\system32\dtu100.dll 2008-01-04 21:57:16 53,248 -c--a-w C:\WINDOWS\system32\dpuGUI10.dll 2008-01-04 21:57:14 593,920 -c--a-w C:\WINDOWS\system32\dpuGUI11.dll 2008-01-04 21:57:14 57,344 -c--a-w C:\WINDOWS\system32\dpv11.dll 2008-01-04 21:57:14 344,064 -c--a-w C:\WINDOWS\system32\dpus11.dll 2008-01-04 21:57:14 294,912 -c--a-w C:\WINDOWS\system32\dpu11.dll 2008-01-04 21:57:14 294,912 -c--a-w C:\WINDOWS\system32\dpu10.dll 2008-01-04 21:57:12 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll 2008-01-04 21:57:10 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll 2008-01-04 21:57:10 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll 2008-01-04 21:57:10 682,496 ----a-w C:\WINDOWS\system32\DivX.dll 2008-01-04 21:56:48 156,992 -c--a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe 2008-01-04 21:56:24 12,288 -c--a-w C:\WINDOWS\system32\DivXWMPExtType.dll 2008-01-01 13:39:58 46 -c--a-w C:\WINDOWS\system32\DonationCoder_rokusnooper_InstallInfo.dat
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] 2006-10-23 00:08 62080 --a------ C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}] 2007-09-28 14:30 521528 --a--c--- C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}] 2008-01-04 18:21 1548624 --a------ C:\PROGRA~1\SPYBOT~1\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] 2007-09-25 01:11 501136 --a--c--- C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] 2007-12-14 13:54 392240 --a------ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}] 2006-08-20 19:55 81920 --a--c--- C:\Program Files\Free Download Manager\iefdmcks.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 18:37] "HostManager"="C:\Program Files\Common Files\AOL\1179865871\ee\AOLSoftware.exe" [2006-11-17 14:21] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11] "IntelliType"="C:\Program Files\Microsoft Hardware\Keyboard\type32.exe" [2002-03-22 05:41] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25] "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 17:05] "IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 16:52] "CICache"="CICache.exe" [2002-09-05 15:21 C:\WINDOWS\CICache.exe] "SmartRAM"="C:\Program Files\IObit\Advanced WindowsCare V2\MemCleaner.exe" [2007-10-29 17:43] "SmartDefrag"="C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" [2008-01-08 00:29] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-06-18 18:11] "SAITEKAUTOCONFIGURE"="C:\Program Files\Saitek\ST\Drv\saicnfig.exe" [] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56] "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "LinkResolveIgnoreLinkInfo"=0 (0x0) "NoResolveSearch"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "LinkResolveIgnoreLinkInfo"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 13:29]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages :\WINDOWS\syste
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
Contents of the 'Scheduled Tasks' folder 2008-03-11 20:07:01 C:\WINDOWS\tasks\AppleSoftwareUpdate.job 2008-03-30 21:00:00 C:\WINDOWS\tasks\SmartDefrag.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2008-03-31 21:49:02 Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully hidden files: 0
**************************************************************************
Completion time: 2008-03-31 21:50:00 C:\ComboFix2.txt ... 2008-03-29 17:54 C:\ComboFix3.txt ... 2008-03-14 21:09
--- E O F ---
|
|
|
|
1 registered and 22 anonymous users are browsing this forum.
Moderator: putasolutions, greysts, bricat, AndrewC, Joe_London, John_McKenna, Mouse, Hello_There, TheFatControlleR, Nanook, Noviciate
Print Thread
|
Forum Permissions
You cannot start new topics
You cannot reply to topics
HTML is disabled
Mark-up is enabled
|
Rating:
Thread views: 0
|
|
|